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The Board of Mydex CIC has discussed your consultation. 


The scope of the guidance is about organisation to organisation data sharing 
between controllers. While it is important that ICO oversees a code for such 
activities, the consultation ignores the fact that the landscape of data sharing is 
changing fundamentally with the introduction of GDPR provisions relating to data 
portability. 


Under GDPR, there are two ways of implementing data portability. 1) where an 
individual asks an organisation to port their data to another organisation 2) where 
an individual asks an organisation for a copy of their data, keeps a copy of this 
data (for example, in a personal data store), and then shares it forward to another 
service provider when and if the individual chooses to do so. 


It is urgent and vital that the ICO develops a Code that a) enables and ensures 
that data portability works easily, safely and efficiently, and b) addresses the 
overlaps and additional considerations that GDPR data portability provisions bring 
to current processes for sharing data between organisations. 


We think this is an oversight in your consultation that urgently needs to be 
rectified. 


(Mydex CIC has developed the infrastructure that enables the second, personal 
data store-based mode of data portability/sharing to operate efficiently, effectively, 
easily and safely. We have a huge amount of insight into issues relating to data 
sharing, but we do not feel that the way you have asked your questions provides 
us with a basis to provide these insights.) 


Yours sincerely 


